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SECRET 


DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11? 


SECURITY COMMITTEE — 
(Effective 23 August 1974) 


- In support of the DCI’s statutory responsibilities and of his efforts to 
improve the Intelligence Community’s product and to achieve more effi- 
- client use of intelligence resources, the community’s security policies and 
procedures must be effective and consistent for the protection of intelli- 
gence and of intelligence sources and methods,? and must ensure time- 
liness and economy in the handling of compartmented information. 
Therefore, pursuant to provisions of Subsection 102 (d) of the National 
Security Act of 1947, as amended, to provisions of NSCID 1 and to para- 
graph 2.b of NSAM 317, a new standing Committee of the USIB is hereby 
established. 


1. Name of the Committee 
- ‘The committee will be known as the Security Committee. 


2. Mission 


The mission of the committee is to provide the means by which the 
Director of Central Intelligence, with the advice of. United States In- 
telligence Board principals, can: 


a. Ensure establishment of security policies and procedures includ- 
ing recommendations for legislation for the protection of intelligence 
and intelligence sources and methods from unauthorized disclosure. 


b. Review and formulate personnel, physical and document security 
policies, standards and practices and dissemination procedures applica- 
ble to all government departments and agencies as such policies, stand- 
ards, practices and procedures relate to the protection of intelligence 


*Supersedes DCID 1/11, effective 23 April 1965 and DCID 1/12 effective 23 
December 1964. 

*?The term intelligence as used in this document applies only to information 
covered by statute, Executive Order, or other authority consonant with the DCI’s 
statutory responsibility for foreign intelligence and for the protection of intelli- 
gence and intelligence sources and methods from unauthorized disclosure. 
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sources and methods in consideration of the effectiveness, risks and 
cost factors involved. 


c. Review and formulate policies and procedures governing the re- 
lease of intelligence to foreign governments and international organiza-. 
tions and the review of classified intelligence proposed for release to 
the public through declassification or other action. With respect to. 
foreign disclosure, ensure that releases are in consonance with U.S. . 


a, ere 
the intelligence itself is accorded a degree of protection equal to that — 


afforded by the United States. With respect to public release, ensure 
‘that disclosure or declassification actions are taken pursuant to proper 
authority and that they are accomplished so as to minimize the risk 
to other intelligence sources and methods. 


d. Ensure that appropriate investigations are made of any unauthor- 
ized disclosure or compromise of intelligence or of intelligence sources 
and methods and that the results of such investigations, along with 
appropriate recommendations, are provided to the Director of Central 
Intelligence. 


f. Review special security and compartmentation procedures and 
develop proposals for any necessary changes to achieve optimum use - 
of intelligence consistent with protection of sensitive intelligence 

_ sources and methods. 


g. Ensure the development, review and maintenance of security 
standards and procedures for the protection of intelligence stored in or 
processed by COMI pULers. 


3. Functions 


The functions of the committee are: 


a. To advise and assist the Director of Central Intelligence as appro- wes 
' priate in the development and review of security policies, standards, . 
procedures and practices for the protection of intelligence and intelli- — 
gence sources and methods from unauthorized disclosures. 


b.. To review, formulate and recommend to the Director of Central 
Intelligence policies, standards and procedures for the dissemination . 
of intelligence materials, for the release of such materials to foreign 
governments, and for the review of classified intelligence proposed for" . 
use in unclassified activities. 

c: On behalf of the Director of Central Intelligence, fo call upon 
departments and agencies to investigate any unauthorized disclosure 
or compromise of intelligence or of intelligence sources and methods 
occurring within their departments and agencies; to report the results 
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of these investigations to the Director of Central Intelligence, through 
the United States Intelligence Board. Such reports will (1) assess the 
disclosure’s impact on the U.S. intelligence process, and its implications 
for national security and foreign relations, (2) describe corrective 
measures taken or needed to prevent such disclosures in the future or 
to minimize the adverse effects of the case at hand, and (3) recommend 
any appropriate additional actions. , 


d. The functions of the committee as they relate to 
25X1 omputer security and special security com- 


partmentation are set forth in attachments 1, 2, and 3. 
4. Community Responsibilities 


a. Upon request of the committee chairman, USIB departments and 
agencies shall furnish to the committee within established security 
safeguards particular information needed by the committee and perti- 
nent to its functions. Temporary material and ad hoc personnel sup-. 
port will be provided to the committee as needed and as mutually 
agreed upon by the departments and agencies represented on the com- 
mittee. 


b. Each USIB principal is responsible for investigation of any unau- 
thorized disclosure or compromise of intelligence or intelligence sources 
and methods occurring within his department or agency. When investi- 
gation determines that the possibility of compromise cannot be dis- 
counted, and the interests of the USIB or another USIB principal are 
involved or affected, the results of investigation will be forwarded to 
the Security Committee for review and possible remedial action as de- 
termined appropriate by the committee. 


5. Composition and Organization 


a. The committee will consist of a full-time chairman designated by 
the DCI, representatives of the chiefs of departments and agencies who 
are members of the USIB, and the representatives of the Departments 

, Of the Army, Navy, and Air Force. The chairman may invite a repre- — 
sentative of the chief of any other department or agency having func- 
tions related to matters being considered by the committee to sit with 
the committee whenever matters within the purview of that depart- 
ment or agency are to be discussed. 


b.. The committee will be supported by 
25X1 abeomimittees” 


as needed and as approved by the DCI and by ad hoc working groups - 
as approved by the chairman. The chairman of subcommittees will be 
designated by the committee chairman with the concurrence of the 
DCI. Membership on the subcommittees and ad hoc working groups 
need not be limited to member agencies of the committee, but may be 
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- extended by the chairman to representatives of other departments and 
- agencies having related functional responsibilities or support capabili- 
ties. 
'¢c. The committee will have a full-time support staff to be provided 
by USIB departments and agencies as arranged and approved by the 
DCI. 


. Rules of Procedure 


‘a. The committee shall meet upon the call of the chairman or at the 
request of any of its members. Items may be placed on the agenda by 
the DCI or by the chairman or any member of the committee. 


_ kb. Decisions or recommendations will be formulated by the chairman 
after giving consideration to the views of the members. At the request 
of a dissenting member, the chairman will refer the decision or rec- 
ommendation along with dissenting opinion or opinions to the DCI. 


W. E. Colby 
Director of Central Intelligence 


— * 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 


(Attachment 1) 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 


(Attachment 2) 


Computer Security. 


The functions of the Security Committee include: 


(1) To review, formulate and recommend to the DCI policies, 
standards, and procedures to protect intelligence data stored or 
processed by computer. 


(2) To advise and assist the DCI, the Intelligence Community 
Staff, Committees of the United States Intelligence Board, USIB 
member agencies and departments, and other intelligence users 
with respect to all computer security issues and to resolve conflicts 
that may arise in connection therewith. 


(3) To formulate and recommend to the DCI resource pro- 

_ gramming objectives for USIB departments and agencies in the 
field of computer security in consideration of current and foreseen 
vulnerabilities and threats and with regard for the effective and 
efficient use of resources; to foster and to monitor an aggressive 
program of computer security research and development in the 
Intelligence Community in order to avoid unwarranted duplication 
and to assure the pursuit of an effective effort at resolving techni- 
cal problems associated with the protection of computer operations. 

(4) To coordinate all aspects of Intelligence Community efforts 
in defense against hostile penetration of Community computer 
systems as feasible to support other Government and national 
efforts aimed at improving computer security technology; to foster 
a coordinated program of Intelligence Community computer se- 
curity training and indoctrination. 

(5) To facilitate within the Intelligence Community the ex- 
change of information relating to computer security threats, vul- _ 
nerabilities, and countermeasures by providing a focal point for the 
evaluation of foreign intentions and capabilities to exploit Com- 
munity computer operations, for central notification: of hostile 
exploitation attempts, for the preparation of damage assessments 
of incidents of foreign exploitation of intelligence computer opera- 
tions, and for the formulation of Community policy on the release 
of computer security information to foreign governments and in- 
ternational organizations. 
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(6) To review, formulate and recommend minimum computer 
security standards, procedures and criteria as guidance for system 
design, evaluation and certification of acceptable levels of security 

_ for computer systems. 


ce Bie 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Atiachnient 3) 
Compartmentation * 


The functions of the Security Committee as they relate to compartmenta. 
tion controls are:? — 


A. To develop and recommend to the DCI, with the advice of 
the United States Intelligence Board, technical guidance for the estab- 
lishment, maintenance and improvement of coordinated Compartuienta- 
tion systems. 


(1) Providing special protection to sensitive intelligence, in- 


telligence information and intelligence sources and methods BOGer 
the authority of Section 9 of Executive Order 11652. 


(2) Ensuring the establishment and disestablishment of com- 
partmentation of intelligence and naeUnBenee information on the 
instructions of the DCI. 


(3) Ensuring coherent control by the DCI of the processes 
for access approvals to compartmented intelligence and intelli- 
gence information and of the processes for dissemination, sanitiza- 
tion or release of such intelligence information. 


(4) Ensuring the establishment and promulgation or appro- 
priate criteria for security and need-to-know access approvals. 


B. To formulate, coordinate, maintain and promulgate technical 
, guidance for use in the administration of compartmentation controls 


at all echelons of department and agency activity, 
Seg ere ee 
(1) Access approval criteria 
25X1 


(2) Physical Security. 


*The term “compartmentation” as used in this directive refers to the system 
whereby special Intelligence Community controls indicating restricted handling 
within collection programs and their end products are applied to certain types _ 
of intelligence information and material. The term does not include Restricted 
Data as defined in Section 11, Atomic Energy Act of 1954, as amended. 
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(3) Document identification, handling, accountability and 
destruction. 
(4) Automatic data processing and associated materials. 


C. To furnish technical cuidance and assistance 


in connection with their sanitization, downgrading, declassi- 
fication and decontrol responsibilities. 


D. To review and survey, when appropriate, with the cooperation 
and assistance of the USIB Principal concerned, the security standards, 
practices and procedures employed by USIB departments and agencies 

in relation to approved compartmentation policies, 
procedures and controls; and to make recommendations for practical 
improvements to the USIB Principals concerned through the DCI. 


_ F. To recommend security policies, in coordination with appropriate 


USIB committees, governing the release or disclosure of compartmented 
intelligence 
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DIRECTOR OF CENTRAL INTELLIGENCE 


Security Committee 
SECOM-D-488 


' § APR 1979 


MEMORANDUM FOR: Security Committee Principals and Observers 


STATINTL FROM: eee 
sxecutive secretary 


SUB.JECT: Unauthorized Disclosures 


’ 


1. Security Committee deliberations at the March 
conference resulted in this subject being selected for 
priority attention during 1979. The attached memorandum 
contains a number of proposals for dealing with the subject. 
With the Chairman's approval, it is forwarded for your 
consideration. 

2. Request that you familiarize yourselves with the 
attached and come to the 11 April 1979 SICOM meeting prepared 
to discuss it. This matter will be taken up under new 
business on the agenda. 


STATINTL 


Attachment 
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DIRECTOR OF CENTRAL INTELLIGENCE 


Security Committee 
y SECOM-D-479 


MEMORANDUM FOR: Chairman, DCI security Committee 


Executive Secretary 


SUBJECT: Unauthorized Disclosures 


1. This topic was selected by the Security Committee 
for priority attention during 1979. 


2. The following actions are proposed toward this 
goal. 


a. Elevate the Unauthorized Disclosures 
Working Group to a permanent Subcommittee of 
the SECOM. Action required: 


1. Draft memorandum for signature 
Chairman to DCI obtaining approval for 
this action. 

2. Necessary charter changes to 
DED. ee Fs 


Comment: The present Chairman of the UDWG has requested 
relict from this ‘duty on the press of other business. 


In recognition that DIA has chaired this activity 
for over a year it nay be advisable to rotate the chair 
at this time. A considerable number of unauthorized 
disclosures are reported by NSA. There may be advantage to 
asking NSA to head this activity. 


b. Improve the Leak Data Base. 
All reports of leaks should be 


accomplished by a completed form which 
will serve to input the computer data base. 
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c. Establish a point of knowledgeable contact 
in each member of the NFIB (preferable the Department's 
representation on the U) Subcommittee. Primarily an 
action officer.) 


d. Reinstitute the concept with the UD 
Subcommittee -of a Fast Reaction Element composed of 
those members whose agencics may be involved in any 
given leak. Functions would be to: 


1. Determine whether the issue is a 
leak of NFI. . 


2. Determine what agencies should be 
asked to initiate immediate investigation and 
to task them accordingly. 


3. Determine whether there should bea 
recommendation to tne DC] requesting an FBI 
investigation. 


4. Should it be determined that further 
investigation would be futile or have no 
salutory effect, cancel various in-house 
investigations and assure that the leak data 
base has been updated. 


e. Establish a contact in the Criminal Division 
of the Attorney General's office and the FBI and 
send copies of each report of leak direct to them. 


f. Establish contacts in the Senate and House 
Intelligence Committees and send them copies of each 
report of leak through the DCI's office of Legislative 
Council. 


eg. Seek DCI agreement to petition the Director 
FBI and the Attorney General to be more willing to do 
investigations of Unauthorized Disclosures. 


1. Obtain support of NFIB members for 
campaiyn. 


2. Present concern at an NFIB meeting. 


3. Obtain support of NSC. 


h. Seek DCL agreement to ask the President for 
an expression of concern about Unauthorized Disclosures. 


2 
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i. Start a publicity push to make every NFI member 
aware that unauthorized disclosures are detrimental. 


Include flyers in cach Intel Pub for a week. 


Put out notices to all personnel in each 
agency. 


For one week, ask everyone who meets with 
the press to report it, naming the reporter 
and the subject(s) covered. 


Put notices on bulletin boards, on tables 
in cafeterias (including the Executive Dining 
Room) . 


Get cable messape to use with each cable for 
one day. 


Get out book dispatch over all network lines - 
leaving it to communicators to attach copy to 
distribution lists. 


j. Seek DCI support for establishing a small 
investigative group composed of representatives of the 
IC that have DCI authority to cross departmental lines 
in pursuit of resolution of unauthorized disclosures of 
National Foreign Intelligence. 


k. Recognize that there are some "authorized 
disclosures" and task the Unauthorized Disclosure 
Subcommittee to work out a mechanism whereby a 
determination can be made as to the category of leak 
(i.e., authorized or unauthorized) before investigations 
are initiated. 


3. These proposals are submitted in the belief that they 
are goal oriented, represent a revitalization of actions and 
interest within the. perogatives of the Security Committee and 
will reflect to the NFIB a positive posture by the Committee. 
Since a major portion of the proposed actions are resource 
consuming, it is suggested that the Committee pick a period, 
say the month of June, and a week within that month, perhaps 
the 2nd week , to devote necessary resources to this effort. 
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4. With approval of the Chairman this memorandum will 
be provided to members for consideration and comments. 


STATINTL 


APPROVED: 


STATINTL 


tober . Gambino 
Chairman 
DCI Security Committee 


Distribution: 
Orig - Addressee return SECOM 
oe CJ SECOM 
1 - SECOM Chrono 
1 - SECOM Subject 
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ONLY YOU CAN PREVENT 
‘THIS MATERIAL FROM BECOMING ° 


AN UNAUTHORIZED DISCLOSURE. 


DO NOT ABUSE THE TRUST THAT 
ACCOMPANIES YOUR ACCESS 
TO THIS AND OTHER U.S. GOVERNMENT 


SENSITIVE INTELLIGENCE. 
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Further needs on Anti Leak Campaign 


Revision of DCID 1/11 to incorporate as Attachment a 
charter for the Unauthorized Disclosures Subcommittee. 


Designation of CSG member as focal point. 
Ideas for flyers on table folders cautioning against leaks. 


Coordination with PI officers in the I.C. and also in 
House and Senate and OLCtNSC. 


Means to get this program brought to the attention of each 
NFIB member through their SECOM member. 


Preparation of material for C/SECOM to present to NFIB. 
(Book a time with Walt Elder.) 
Paper for C/SECOM to present to the DCI outlining this 


campaign and seeking his support and approval to present 
to NFIB. 
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